Splunk Enterprise

How can I get a Splunk 0 MB license for legacy log access

tanjil
New Member

Hi everyone,

We already have a Splunk Cloud environment, and on-premises we have a Splunk deployment server. However, the on-prem deployment server currently has no license — it's only used to manage forwarders and isn’t indexing any data.

We now have some legacy logs stored locally that we’d like to search through without ingesting new data. For this, we’re looking to get a Splunk 0 MB license (search-only) on the deployment server.

Is there any way to request or generate a 0 MB license for this use case?

Thanks in advance for your help!

Labels (3)
0 Karma

livehybrid
Super Champion

Hi @tanjil 

As you are a Splunk Cloud customer you are entitled to a "0-byte" license which allows you to use non-indexing components without restriction (e.g. auth/kvstore/forwarding/accessing previously indexed data etc etc) - Check out https://splunk.my.site.com/customer/s/article/0-byte-license-for-Deployment-Server-or-Heavy-Forwarde... for more information. 

Basically this is a perpetual 0-byte license so you can perform your usual HF/DS work.

Just open a case via https://www.splunk.com/support and they should issue it pretty quickly.

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

0 Karma

kiran_panchavat
Influencer

@tanjil 

I recommend raising a Splunk Support ticket to request the 0 MB license file. Please ensure that the support case is submitted under your valid entitlement. Recently, one of our customers submitted a similar request, and Splunk provided the 0 MB license file for their heavy forwarder..

Did this help? If yes, please consider giving kudos, marking it as the solution, or commenting for clarification — your feedback keeps the community going!

PickleRick
SplunkTrust
SplunkTrust

First thing to do would be to call out to your local friendly Splunk Partner or any other sales channel you might have used before. If you are a current Cloud customer you should be entitled to a 0 bytes license. It's typically used for a forwarder, but might also be used for accessing previously indexed data.

0 Karma
Get Updates on the Splunk Community!

Why You Can't Miss .conf25: Unleashing the Power of Agentic AI with Splunk & Cisco

The Defining Technology Movement of Our Lifetime The advent of agentic AI is arguably the defining technology ...

Deep Dive into Federated Analytics: Unlocking the Full Power of Your Security Data

In today’s complex digital landscape, security teams face increasing pressure to protect sprawling data across ...

Your summer travels continue with new course releases

Summer in the Northern hemisphere is in full swing, and is often a time to travel and explore. If your summer ...